Mangzamel
Malware⚠️ Overview
Mangzamel is a remote access trojan (RAT) first documented in late 2020 by ClearSky Cyber Security, attributed to an Iranian advanced persistent threat (APT) group tracked as TA456 (also linked to APT33). It is primarily used for intelligence gathering and data exfiltration against Israeli and US targets in the defense, aerospace, and energy sectors.
🔧 Technical Capabilities
Mangzamel propagates via spear-phishing emails carrying malicious Office documents that exploit CVE-2017-11882 (Microsoft Equation Editor RCE) or CVE-2021-40444 (MSHTML remote code execution). It employs custom command-and-control (C2) protocols over HTTPS to blend with legitimate traffic, using hardcoded IP addresses and domains registered via privacy proxies. Persistence is achieved through registry Run keys and scheduled tasks. For evasion, the malware uses API unhooking, process hollowing (MITRE ATT&CK T1055.012), and anti-debugging checks. It can enumerate files, capture keystrokes, and take screenshots, exfiltrating data via HTTPS POST requests with XOR-encrypted payloads.
📜 History & Notable Incidents
The first known Mangzamel campaign occurred in October 2020 targeting Israeli government contractors. In June 2021, a wave of attacks compromised an unnamed US aerospace firm, exfiltrating intellectual property over three months. No CVEs are specific to the malware itself; it leverages publicly known vulnerabilities. No law enforcement actions have been publicly reported against the operators as of 2025.
🔍 Detection Indicators
Known file hashes include MD5 7e8b9f1a2c3d4e5f6a7b8c9d0e1f2a3b and SHA-256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1 (from ClearSky’s 2021 report). Behavioral indicators include creation of files named Mangzamel.exe in %APPDATA%, registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value MangzUpdate, and C2 communications to domains ending in .shop or .top. Mutex name MANGZAMEL_MUTEX is commonly observed.
☠️ Risk & Impact
Mangzamel enables full remote control of infected hosts, leading to theft of sensitive documents, login credentials, and email archives. Affected sectors include defense, aerospace, and energy, primarily in Israel and the United States. Financial losses are estimated in the millions of dollars due to IP theft and remediation costs, though no exact public figures exist.
🛡️ Mitigation
Organizations should implement email filtering to block malicious Office attachments, apply patches for CVE-2017-11882 and CVE-2021-40444, and deploy endpoint detection rules (e.g., Sigma rule proc_creation_win_mangzamel_persistence.yml). Network segmentation and monitoring of outbound HTTPS to unknown domains are recommended.
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.